LIVE · cybersecurity feed
Live wire
CVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants WarnCVE-2023-49105 · Philippine Nuclear and Naval Targets Hit by Suspected Chinese OperatorTerminalFix campaign deploys a reverse tunnel through multistage intrusionPerturbation Probing: A New Diagnostic for the Fragility of LLM SafetyResearcher shows how Claude Code can be tricked simply by asking it to summarize a websiteCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was VulnerableATF confirms cyberattack hit system containing info on its investigation targets

remote code execution

CVE-2026-82078critical

PaperCut releases second emergency patch for exploited flaws

PaperCut has issued a second emergency patch for its NG and MF print management software to address two critical vulnerabilities. These flaws, CVE-2026-82078 and CVE-2026-81578, were found to be bypassable by initial fixes and allow attackers to achieve authentication bypass and remote code execution. The company urges all customers to install the latest patch, even if they applied the first one, and to implement network access controls as a precautionary measure.

CVE-2026-73570critical

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

CISA has added a critical vulnerability in Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-73570, allows unauthenticated remote code execution and is being actively exploited by threat actors. Zimbra released a patch for the vulnerability less than a month before exploitation was confirmed.

CVE-2026-73570critical

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Attackers are actively exploiting a critical vulnerability in Zimbra Collaboration (ZCS) that allows for unauthenticated remote code execution. The flaw, identified as CVE-2026-73570 with a CVSS score of 8.9, stems from improper input sanitization in the SNMP notification processing. Exploitation can lead to the execution of arbitrary operating system commands as the Zimbra user. Zimbra has released version 10.1.20 to patch this vulnerability, and CERT Polska is urging users to check their logs for signs of compromise.

geoservercritical

Hackers Exploiting Unpatched GeoServer Zero-Day

A critical zero-day vulnerability in GeoServer is being actively exploited by hackers. The SQL injection flaw could enable attackers to achieve remote code execution on vulnerable systems.

CVE-2026-20147high

Cisco Identity Services Engine Vulnerable to Command Injection

A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.

CVE-2026-20181high

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal

A directory traversal vulnerability in Cisco Identity Services Engine could allow authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has a CVSS score of 7.2, indicating a significant security risk.

nginxcritical

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

A critical vulnerability has been discovered in the NGINX HTTP WebDAV module that could allow remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied data during WebDAV request parsing, leading to an integer underflow. This could enable an attacker to run code with the privileges of the service account on affected NGINX installations.

CVE-2026-42533critical

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

A critical vulnerability (CVE-2026-42533) has been discovered in NGINX, potentially allowing remote attackers to crash worker processes or even execute arbitrary code. The flaw, present in versions from 0.9.6 up to 1.31.2, arises from a specific configuration involving regex-based maps and string expressions. While F5 has released patches, researchers suggest that existing mitigations might not be entirely effective, emphasizing the need for immediate upgrades.

CVE-2026-60137high

Two High-Severity WordPress Vulnerabilities Require Immediate Patching

WordPress version 6.9 has been impacted by two significant security flaws. One vulnerability allows for SQL injection, while the other, a REST API issue, could lead to remote code execution. Both have been addressed in the latest security release, version 7.0.2.

CVE-2026-12958high

Bug in top AI coding agents shows that Unix-era security headaches never really die

A vulnerability dubbed "GhostApproval" has been discovered in at least six popular AI coding assistants, allowing them to access files outside their designated workspaces and potentially execute remote code. The flaw exploits symbolic links, a long-standing security issue, to trick agents into writing malicious content, such as SSH keys, to sensitive system files. While some vendors have patched the issue and assigned CVEs, others have downplayed the risk or are yet to release fixes.